Vulnerability in SNMPv3 Service May Allow Access to Plaintext credentials
CVE-2024-8452

7.5HIGH

What is CVE-2024-8452?

Certain switch models from PLANET Technology utilize outdated algorithms for authentication and encryption within the SNMPv3 service. This vulnerability allows attackers to access plaintext SNMPv3 credentials, potentially compromising security. Users of affected models should evaluate their network configurations and consider mitigating strategies to safeguard against unauthorized access.

Affected Version(s)

GS-4210-24P2S hardware 3.0 0 < 3.305b240802

GS-4210-24PL4C hardware 2.0 0 < 2.305b240719

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-8452 : Vulnerability in SNMPv3 Service May Allow Access to Plaintext credentials